MikeTrendsTrends right now

search

OWASP

Trends

  1. 1

    OWASP Noir is an open-source static analysis tool designed to identify attack surfaces in code. Coverage highlights its ability to help developers and security teams map endpoints and potential vulnerabilities early in development, adding to OWASP's portfolio of freely available application security resources.

  2. 2
    Security experts debate account recovery notification rules●Account recovery is the weak link, and I think the framing is off. NIST 800-63-4 and OWASP ASVS require notifying the owMmastodonTechnologyCybersecurity11 d ago

    A security practitioner argues that account recovery flows remain the weakest link in authentication, and that the framing around them is wrong. Standards like NIST 800-63-4 and OWASP ASVS require notifying an account owner only after a password reset completes, staying silent at the attempt stage to prevent account enumeration. The practitioner contends the reset attempt itself is the one event no standard requires services to flag, leaving users blind to attacks in progress.

  3. 3
    OWASP Noir open-source tool maps exposed app endpoints●This looks like a powerful, helpful tool! OWASP Noir is an open-source static analysis tool that reads an application’sMmastodonTechnologyCybersecurity21 d ago

    OWASP Noir, an open-source static analysis tool, is drawing attention in the cybersecurity community. The tool reads an application's source code and automatically lists the endpoints it exposes, helping developers and security teams map an app's attack surface during code review. Commenters describe it as a powerful and helpful addition to the open-source security toolkit.